Urban Surveillance: Recent drone footage from the San Francisco Police Department has highlighted a new chapter in detailed urban surveillance. Concurrently, the San Francisco City Attorney’s Office has sent letters to tech giants Apple and Google, demanding the removal of 13 AI-defying “face-swapping” apps from their app stores, which predominantly target women and girls.
In June, WIRED revealed insights into Meta’s controversial NameTag facial recognition system, yet company executives have provided vague and inconsistent statements regarding its existence. We took a comprehensive look, uncovering the claims and the realities surrounding this system.
During a speech on Thursday, former President Donald Trump repeated unfounded allegations of interference in the 2020 U.S. election. He claimed to have substantial evidence in documents shared on the White House website; however, these documents did not corroborate his assertions and, in some instances, contradicted them.
With the rapid expansion of AI tools and their capabilities, tech leader Anthropic urges U.S. states to regulate AI technologies. Cesar Fernandez, Anthropic’s director of U.S. state and local government relations, discussed California and New York’s AI transparency mandates, stating, “While the Transparency Safety Act of 2025 is an essential first step, the rapid advancement of AI technologies necessitates corresponding policy responses.”
Stay informed with our weekly roundup of significant security and privacy news. Click the heading for complete insights, and remember to prioritize your safety while outside.
The astrology-themed app Stardust, which tracks menstrual cycles, shares users’ reproductive health information—including contraceptive types, pregnancy status, mood, and specific symptoms—with an unnamed data company. According to BBC, this was highlighted in an audit conducted by the Mozilla Foundation in collaboration with Harvard University’s Berkman Klein Center.
Stardust received a score of 2 out of 10 from Mozilla, marking it among the least secure. The audit revealed that the app transmits data to analytics firm RudderStack upon opening, even before any input is provided. When users log symptoms, details are sent along with a persistent user ID, without options to prevent sharing within the app. Furthermore, Stardust shares advertising identifiers with Facebook, linking user behavior to existing profiles on the platform. The company informed TechCrunch that they have never received any legal requests for user data.
Euki, an app managed by a non-profit organization, achieved a perfect score of 10. No accounts needed, ensuring users’ health data remains on their devices. Users can set PINs, schedule automatic deletions, and display decoy screens in emergencies. However, its in-app browser accesses typical web trackers, albeit resetting identifiers for better privacy.
Russia’s FSB has garnered a reputation for sophisticated cyber espionage, collaborating with the GRU military intelligence agency for impactful cyber assaults. Recent EU and UK sanctions, along with insights from U.S. cybersecurity agencies, led to the identification of a cyberattack on Poland’s power grid linked to the FSB’s Center 16. This incident represents a rare instance where Russian authorities initiated a cyberattack that nearly caused widespread power disruptions. Initially attributed to the GRU’s Sandworm, Poland’s Computer Emergency Response Team later connected the attack to the FSB, a conclusion gaining affirmation from Western governments. It seems the FSB may be adopting the aggressive tactics characteristic of the GRU.
Kaspersky Lab, a Russian cybersecurity firm, has faced scrutiny over its connections with the Russian government, including bans from U.S. government use. Despite limited evidence proving these ties, reports by Reuters reveal that Denis Obresko, facing hacking charges, was formerly employed at Kaspersky. He allegedly took part in hacking operations targeting numerous NATO nations and at least 11 U.S. companies after his tenure at Kaspersky, where he was believed to have supported Russian intelligence efforts.
Obresko has pleaded not guilty. Kaspersky’s response to Reuters states: “The crimes charged are not related to the individual’s role or responsibilities at Kaspersky Lab.”
A concerning case has emerged regarding the Department of Homeland Security (DHS), where officials dismissed genuine hacker intrusion indicators on a data-sharing platform as false positives. HSIN, used for sharing unclassified information, was compromised two months ago. Analysts detected unusual activity, including file alterations and server hijacking, yet these were miscategorized as benign.
As the threat resurfaced, analysts mistakenly downplayed the intrusion again. The circumstances surrounding these misjudgments remain unclear, yet highlight a growing challenge for federal analysts in detecting advanced hacking techniques. Although HSIN only contains unclassified data, the information is “highly sensitive,” posing potential risks to national security, as stated by Deputy Commissioner Mark Warner following the leak.
AI music startup Suno recently faced scrutiny for using millions of songs, lyrics, and podcasts from platforms like YouTube Music, Deezer, and stock audio libraries to train its model. Hackers compromised internal data, revealing account information for numerous users, including emails and payment details. Suno reportedly used advanced methods to scrape audio from these platforms, raising concerns over its training practices and data management.
The leaked files indicate that Suno collected approximately 113,879 hours of audio from YouTube alone, with additional content from other sources, amounting to several decades of music. A hacker named ellie.191 claimed involvement in a breach affecting this data. Despite a claim of fair use following a settlement with Warner Music Group, the breach’s details revealed issues with outdated coding and a lack of notification to affected users.
Source: www.wired.com

